MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 33446f98e49714ac509ef7a5f542c9bb557968f2a640f104ce27fca80d576580. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: 33446f98e49714ac509ef7a5f542c9bb557968f2a640f104ce27fca80d576580
SHA3-384 hash: 71f2c8a161da52705d9374421a1d0cbe3c965fa38c13b9fc32d1409748df0d42cdb7ff0d3f6326418ad4c5287ac2ece0
SHA1 hash: 0c355149bc133f75e03c889a94bfe0aaf5c2c8ef
MD5 hash: 9fdf05841c063a2f751e348bfc6f2ec4
humanhash: football-happy-orange-alanine
File name:1.sh
Download: download sample
Signature Mirai
File size:3'194 bytes
First seen:2026-02-18 18:39:41 UTC
Last seen:2026-02-19 11:16:42 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:is0csxGsiUsFJYsb2sDSskTkLscUs7YLsKaJsF6sTus6ssQssfgW:iCfEPBtoe5Le3LQ4FW
TLSH T13661B5CA02C58B715DAA896373E5E4C97D9DE0AE2082DF36CFEC34F2084DD1871595E2
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://157.245.203.34/ambatukam/rizzx.x862fdea35950d735f2f97a13f7189d7951ae9d27c5ae504448b1ade310edb8e5b7 Miraimirai opendir
http://157.245.203.34/ambatukam/rizzx.mipsfef2eb6f39205bb097d7e44f7804fc04616c00a6d0db98e03ef96874244f7083 Miraimirai opendir
http://157.245.203.34/ambatukam/rizzx.arcc612ce7b5788adcc74e1fbf45a31d416152a520c5d6d7f04e7297f6ecc96b049 Miraimirai opendir
http://157.245.203.34/ambatukam/rizzx.i468n/an/aelf ua-wget
http://157.245.203.34/ambatukam/rizzx.i68654b6c012bd3bcda4dac68ff91783687efecb33da8c034c3da78503c4053553e6 Miraimirai opendir
http://157.245.203.34/ambatukam/rizzx.x86_645c705c70e87615cd2d226105f2079a95836db427c84d38baa2bb821daa881cf1 Miraimirai opendir
http://157.245.203.34/ambatukam/rizzx.mpsl2619a10770b6735120ff951145cbbfdc349a1c93557fdf997a56c72f05bff4b1 Miraimirai opendir
http://157.245.203.34/ambatukam/rizzx.armac28aa2fbe9ff0528536fce7aa701f01842149ec8a0a4c435d682f44de054160 Miraimirai opendir
http://157.245.203.34/ambatukam/rizzx.arm5a3344fdea80d4978a5fe3ef2543dad8b14cdb2929a137ff5ce846a3f609d55fe Miraimirai opendir
http://157.245.203.34/ambatukam/rizzx.arm6bc9c9c728baac458f606c8901296cb7295b08f0f13818b4d89684d8fbf5e27c5 Miraimirai opendir
http://157.245.203.34/ambatukam/rizzx.arm7f9132d227a1f0e08d98ac0185264d356e93b15a7c1912c35c1f3a98a61cb1c4c Miraimirai opendir
http://157.245.203.34/ambatukam/rizzx.ppc2234c5ad4f38df0ddb71f87a3789a2cf861f4f2bd7db843c1bd1ef591a810b1b Miraimirai opendir
http://157.245.203.34/ambatukam/rizzx.spc319d9d1e529560228df3c58f29f8090ad8cd087ce992ba2e3e92b59502178e0e Miraimirai opendir
http://157.245.203.34/ambatukam/rizzx.m68k58f6f5ac44d446bb9eceb9eceb7849cdf43052e68e88dec6278d049c0c3f8e63 Miraimirai opendir
http://157.245.203.34/ambatukam/rizzx.sh4e9e2e3ce2221dc85c5864337b54ae4863ead655db85c711b87a8bd2ecbee5d57 Miraimirai opendir

Intelligence


File Origin
# of uploads :
3
# of downloads :
48
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=0aaea0d8-1800-0000-cbba-1f5cb5070000 pid=1973 /usr/bin/sudo guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974 /tmp/sample.bin guuid=0aaea0d8-1800-0000-cbba-1f5cb5070000 pid=1973->guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974 execve guuid=d4f601de-1800-0000-cbba-1f5cb7070000 pid=1975 /usr/bin/cp guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=d4f601de-1800-0000-cbba-1f5cb7070000 pid=1975 execve guuid=d7eb57e6-1800-0000-cbba-1f5cc0070000 pid=1984 /usr/bin/wget net send-data write-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=d7eb57e6-1800-0000-cbba-1f5cc0070000 pid=1984 execve guuid=07641928-1900-0000-cbba-1f5c3c080000 pid=2108 /usr/bin/curl net send-data write-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=07641928-1900-0000-cbba-1f5c3c080000 pid=2108 execve guuid=27dbe36a-1900-0000-cbba-1f5ce1080000 pid=2273 /usr/bin/chmod guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=27dbe36a-1900-0000-cbba-1f5ce1080000 pid=2273 execve guuid=9eb21773-1900-0000-cbba-1f5ce2080000 pid=2274 /tmp/rizzx.x86 net guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=9eb21773-1900-0000-cbba-1f5ce2080000 pid=2274 execve guuid=e16f92a0-1a00-0000-cbba-1f5c3c0b0000 pid=2876 /usr/bin/rm delete-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=e16f92a0-1a00-0000-cbba-1f5c3c0b0000 pid=2876 execve guuid=79d34ca1-1a00-0000-cbba-1f5c3e0b0000 pid=2878 /usr/bin/wget net send-data write-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=79d34ca1-1a00-0000-cbba-1f5c3e0b0000 pid=2878 execve guuid=7ddf45f1-1a00-0000-cbba-1f5ca90b0000 pid=2985 /usr/bin/curl net send-data write-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=7ddf45f1-1a00-0000-cbba-1f5ca90b0000 pid=2985 execve guuid=7bbf1346-1b00-0000-cbba-1f5c340c0000 pid=3124 /usr/bin/chmod guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=7bbf1346-1b00-0000-cbba-1f5c340c0000 pid=3124 execve guuid=0b00d246-1b00-0000-cbba-1f5c370c0000 pid=3127 /usr/bin/bash guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=0b00d246-1b00-0000-cbba-1f5c370c0000 pid=3127 clone guuid=acc6594a-1b00-0000-cbba-1f5c3f0c0000 pid=3135 /usr/bin/rm delete-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=acc6594a-1b00-0000-cbba-1f5c3f0c0000 pid=3135 execve guuid=23e8b44a-1b00-0000-cbba-1f5c410c0000 pid=3137 /usr/bin/wget net send-data write-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=23e8b44a-1b00-0000-cbba-1f5c410c0000 pid=3137 execve guuid=a13916b1-1b00-0000-cbba-1f5cae0c0000 pid=3246 /usr/bin/curl net send-data write-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=a13916b1-1b00-0000-cbba-1f5cae0c0000 pid=3246 execve guuid=96ed731a-1c00-0000-cbba-1f5c740d0000 pid=3444 /usr/bin/chmod guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=96ed731a-1c00-0000-cbba-1f5c740d0000 pid=3444 execve guuid=a1d7ed1a-1c00-0000-cbba-1f5c760d0000 pid=3446 /usr/bin/bash guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=a1d7ed1a-1c00-0000-cbba-1f5c760d0000 pid=3446 clone guuid=f500501c-1c00-0000-cbba-1f5c7b0d0000 pid=3451 /usr/bin/rm delete-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=f500501c-1c00-0000-cbba-1f5c7b0d0000 pid=3451 execve guuid=33c3e11c-1c00-0000-cbba-1f5c7d0d0000 pid=3453 /usr/bin/wget net send-data guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=33c3e11c-1c00-0000-cbba-1f5c7d0d0000 pid=3453 execve guuid=86a5a547-1c00-0000-cbba-1f5cca0d0000 pid=3530 /usr/bin/curl net send-data write-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=86a5a547-1c00-0000-cbba-1f5cca0d0000 pid=3530 execve guuid=1a2a7973-1c00-0000-cbba-1f5c220e0000 pid=3618 /usr/bin/chmod guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=1a2a7973-1c00-0000-cbba-1f5c220e0000 pid=3618 execve guuid=a3c70074-1c00-0000-cbba-1f5c240e0000 pid=3620 /usr/bin/bash guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=a3c70074-1c00-0000-cbba-1f5c240e0000 pid=3620 clone guuid=44ff3d74-1c00-0000-cbba-1f5c250e0000 pid=3621 /usr/bin/rm delete-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=44ff3d74-1c00-0000-cbba-1f5c250e0000 pid=3621 execve guuid=dbc4b674-1c00-0000-cbba-1f5c270e0000 pid=3623 /usr/bin/wget net send-data write-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=dbc4b674-1c00-0000-cbba-1f5c270e0000 pid=3623 execve guuid=c981f7b2-1c00-0000-cbba-1f5cc40e0000 pid=3780 /usr/bin/curl net send-data write-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=c981f7b2-1c00-0000-cbba-1f5cc40e0000 pid=3780 execve guuid=1896aff5-1c00-0000-cbba-1f5c7d0f0000 pid=3965 /usr/bin/chmod guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=1896aff5-1c00-0000-cbba-1f5c7d0f0000 pid=3965 execve guuid=48547bf6-1c00-0000-cbba-1f5c810f0000 pid=3969 /tmp/rizzx.i686 net guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=48547bf6-1c00-0000-cbba-1f5c810f0000 pid=3969 execve guuid=4ce96625-1e00-0000-cbba-1f5cab120000 pid=4779 /usr/bin/rm delete-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=4ce96625-1e00-0000-cbba-1f5cab120000 pid=4779 execve guuid=5187f725-1e00-0000-cbba-1f5cae120000 pid=4782 /usr/bin/wget net send-data write-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=5187f725-1e00-0000-cbba-1f5cae120000 pid=4782 execve guuid=a5b09c67-1e00-0000-cbba-1f5c67130000 pid=4967 /usr/bin/curl net send-data write-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=a5b09c67-1e00-0000-cbba-1f5c67130000 pid=4967 execve guuid=e197d6a7-1e00-0000-cbba-1f5c24140000 pid=5156 /usr/bin/chmod guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=e197d6a7-1e00-0000-cbba-1f5c24140000 pid=5156 execve guuid=db1f1aa8-1e00-0000-cbba-1f5c26140000 pid=5158 /tmp/rizzx.x86_64 mprotect-exec net guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=db1f1aa8-1e00-0000-cbba-1f5c26140000 pid=5158 execve guuid=306115d3-1f00-0000-cbba-1f5c8a140000 pid=5258 /usr/bin/rm delete-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=306115d3-1f00-0000-cbba-1f5c8a140000 pid=5258 execve guuid=2f4875d3-1f00-0000-cbba-1f5c8b140000 pid=5259 /usr/bin/wget net send-data write-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=2f4875d3-1f00-0000-cbba-1f5c8b140000 pid=5259 execve guuid=6521b72c-2000-0000-cbba-1f5c93140000 pid=5267 /usr/bin/curl net send-data write-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=6521b72c-2000-0000-cbba-1f5c93140000 pid=5267 execve guuid=acf5a187-2000-0000-cbba-1f5c94140000 pid=5268 /usr/bin/chmod guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=acf5a187-2000-0000-cbba-1f5c94140000 pid=5268 execve guuid=fd050288-2000-0000-cbba-1f5c95140000 pid=5269 /usr/bin/bash guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=fd050288-2000-0000-cbba-1f5c95140000 pid=5269 clone guuid=9ea67089-2000-0000-cbba-1f5c97140000 pid=5271 /usr/bin/rm delete-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=9ea67089-2000-0000-cbba-1f5c97140000 pid=5271 execve guuid=8b49e989-2000-0000-cbba-1f5c98140000 pid=5272 /usr/bin/wget net send-data write-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=8b49e989-2000-0000-cbba-1f5c98140000 pid=5272 execve guuid=254463c6-2000-0000-cbba-1f5c99140000 pid=5273 /usr/bin/curl net send-data write-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=254463c6-2000-0000-cbba-1f5c99140000 pid=5273 execve guuid=4e571d09-2100-0000-cbba-1f5ca1140000 pid=5281 /usr/bin/chmod guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=4e571d09-2100-0000-cbba-1f5ca1140000 pid=5281 execve guuid=76eeb109-2100-0000-cbba-1f5ca3140000 pid=5283 /usr/bin/bash guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=76eeb109-2100-0000-cbba-1f5ca3140000 pid=5283 clone guuid=0ad1d60a-2100-0000-cbba-1f5ca6140000 pid=5286 /usr/bin/rm delete-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=0ad1d60a-2100-0000-cbba-1f5ca6140000 pid=5286 execve guuid=6b2c2f0b-2100-0000-cbba-1f5ca7140000 pid=5287 /usr/bin/wget net send-data write-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=6b2c2f0b-2100-0000-cbba-1f5ca7140000 pid=5287 execve guuid=5f4ca648-2100-0000-cbba-1f5cae140000 pid=5294 /usr/bin/curl net send-data write-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=5f4ca648-2100-0000-cbba-1f5cae140000 pid=5294 execve guuid=39f8bf86-2100-0000-cbba-1f5cc0140000 pid=5312 /usr/bin/chmod guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=39f8bf86-2100-0000-cbba-1f5cc0140000 pid=5312 execve guuid=85cc5b87-2100-0000-cbba-1f5cc1140000 pid=5313 /usr/bin/bash guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=85cc5b87-2100-0000-cbba-1f5cc1140000 pid=5313 clone guuid=a79ca788-2100-0000-cbba-1f5cc3140000 pid=5315 /usr/bin/rm delete-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=a79ca788-2100-0000-cbba-1f5cc3140000 pid=5315 execve guuid=98214389-2100-0000-cbba-1f5cc4140000 pid=5316 /usr/bin/wget net send-data write-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=98214389-2100-0000-cbba-1f5cc4140000 pid=5316 execve guuid=782f03dd-2100-0000-cbba-1f5cc5140000 pid=5317 /usr/bin/curl net send-data write-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=782f03dd-2100-0000-cbba-1f5cc5140000 pid=5317 execve guuid=a61b3b2d-2200-0000-cbba-1f5cc6140000 pid=5318 /usr/bin/chmod guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=a61b3b2d-2200-0000-cbba-1f5cc6140000 pid=5318 execve guuid=31afd12d-2200-0000-cbba-1f5cc7140000 pid=5319 /usr/bin/bash guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=31afd12d-2200-0000-cbba-1f5cc7140000 pid=5319 clone guuid=466e1d2f-2200-0000-cbba-1f5cc9140000 pid=5321 /usr/bin/rm delete-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=466e1d2f-2200-0000-cbba-1f5cc9140000 pid=5321 execve guuid=66cfb12f-2200-0000-cbba-1f5cca140000 pid=5322 /usr/bin/wget net send-data write-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=66cfb12f-2200-0000-cbba-1f5cca140000 pid=5322 execve guuid=5094d780-2200-0000-cbba-1f5ccb140000 pid=5323 /usr/bin/curl net send-data write-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=5094d780-2200-0000-cbba-1f5ccb140000 pid=5323 execve guuid=6b3741d6-2200-0000-cbba-1f5ccc140000 pid=5324 /usr/bin/chmod guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=6b3741d6-2200-0000-cbba-1f5ccc140000 pid=5324 execve guuid=6268d5d6-2200-0000-cbba-1f5ccd140000 pid=5325 /usr/bin/bash guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=6268d5d6-2200-0000-cbba-1f5ccd140000 pid=5325 clone guuid=f183f2d7-2200-0000-cbba-1f5ccf140000 pid=5327 /usr/bin/rm delete-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=f183f2d7-2200-0000-cbba-1f5ccf140000 pid=5327 execve guuid=5e0689d8-2200-0000-cbba-1f5cd0140000 pid=5328 /usr/bin/wget net send-data write-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=5e0689d8-2200-0000-cbba-1f5cd0140000 pid=5328 execve guuid=b766e517-2300-0000-cbba-1f5cd1140000 pid=5329 /usr/bin/curl net send-data write-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=b766e517-2300-0000-cbba-1f5cd1140000 pid=5329 execve guuid=77fd9f58-2300-0000-cbba-1f5cd2140000 pid=5330 /usr/bin/chmod guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=77fd9f58-2300-0000-cbba-1f5cd2140000 pid=5330 execve guuid=fbd23559-2300-0000-cbba-1f5cd3140000 pid=5331 /usr/bin/bash guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=fbd23559-2300-0000-cbba-1f5cd3140000 pid=5331 clone guuid=b0be715a-2300-0000-cbba-1f5cd5140000 pid=5333 /usr/bin/rm delete-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=b0be715a-2300-0000-cbba-1f5cd5140000 pid=5333 execve guuid=848c025b-2300-0000-cbba-1f5cd6140000 pid=5334 /usr/bin/wget net send-data write-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=848c025b-2300-0000-cbba-1f5cd6140000 pid=5334 execve guuid=45c63fab-2300-0000-cbba-1f5cd7140000 pid=5335 /usr/bin/curl net send-data write-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=45c63fab-2300-0000-cbba-1f5cd7140000 pid=5335 execve guuid=9b8a45fe-2300-0000-cbba-1f5cd8140000 pid=5336 /usr/bin/chmod guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=9b8a45fe-2300-0000-cbba-1f5cd8140000 pid=5336 execve guuid=46d4d1fe-2300-0000-cbba-1f5cd9140000 pid=5337 /usr/bin/bash guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=46d4d1fe-2300-0000-cbba-1f5cd9140000 pid=5337 clone guuid=75ac0700-2400-0000-cbba-1f5cdb140000 pid=5339 /usr/bin/rm delete-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=75ac0700-2400-0000-cbba-1f5cdb140000 pid=5339 execve guuid=2c209a00-2400-0000-cbba-1f5cdc140000 pid=5340 /usr/bin/wget net send-data write-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=2c209a00-2400-0000-cbba-1f5cdc140000 pid=5340 execve guuid=612dbc54-2400-0000-cbba-1f5cdd140000 pid=5341 /usr/bin/curl net send-data write-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=612dbc54-2400-0000-cbba-1f5cdd140000 pid=5341 execve guuid=ae3260ab-2400-0000-cbba-1f5cde140000 pid=5342 /usr/bin/chmod guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=ae3260ab-2400-0000-cbba-1f5cde140000 pid=5342 execve guuid=0d70f4ab-2400-0000-cbba-1f5cdf140000 pid=5343 /usr/bin/bash guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=0d70f4ab-2400-0000-cbba-1f5cdf140000 pid=5343 clone guuid=0d4d1aad-2400-0000-cbba-1f5ce1140000 pid=5345 /usr/bin/rm delete-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=0d4d1aad-2400-0000-cbba-1f5ce1140000 pid=5345 execve guuid=8250b0ad-2400-0000-cbba-1f5ce2140000 pid=5346 /usr/bin/wget net send-data write-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=8250b0ad-2400-0000-cbba-1f5ce2140000 pid=5346 execve guuid=57a0af02-2500-0000-cbba-1f5ce3140000 pid=5347 /usr/bin/curl net send-data write-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=57a0af02-2500-0000-cbba-1f5ce3140000 pid=5347 execve guuid=fb81535c-2500-0000-cbba-1f5ce4140000 pid=5348 /usr/bin/chmod guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=fb81535c-2500-0000-cbba-1f5ce4140000 pid=5348 execve guuid=f15ceb5c-2500-0000-cbba-1f5ce5140000 pid=5349 /usr/bin/bash guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=f15ceb5c-2500-0000-cbba-1f5ce5140000 pid=5349 clone guuid=695d115e-2500-0000-cbba-1f5ce7140000 pid=5351 /usr/bin/rm delete-file guuid=a492a0dc-1800-0000-cbba-1f5cb6070000 pid=1974->guuid=695d115e-2500-0000-cbba-1f5ce7140000 pid=5351 execve e7225e39-f15e-5900-a414-2b8f44acb4a1 157.245.203.34:80 guuid=d7eb57e6-1800-0000-cbba-1f5cc0070000 pid=1984->e7225e39-f15e-5900-a414-2b8f44acb4a1 send: 148B guuid=07641928-1900-0000-cbba-1f5c3c080000 pid=2108->e7225e39-f15e-5900-a414-2b8f44acb4a1 send: 97B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=9eb21773-1900-0000-cbba-1f5ce2080000 pid=2274->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e4f7ed73-1900-0000-cbba-1f5ce3080000 pid=2275 /tmp/rizzx.x86 guuid=9eb21773-1900-0000-cbba-1f5ce2080000 pid=2274->guuid=e4f7ed73-1900-0000-cbba-1f5ce3080000 pid=2275 clone guuid=d4ce77a0-1a00-0000-cbba-1f5c3a0b0000 pid=2874 /tmp/rizzx.x86 guuid=9eb21773-1900-0000-cbba-1f5ce2080000 pid=2274->guuid=d4ce77a0-1a00-0000-cbba-1f5c3a0b0000 pid=2874 clone guuid=807581a0-1a00-0000-cbba-1f5c3b0b0000 pid=2875 /tmp/rizzx.x86 net send-data zombie guuid=9eb21773-1900-0000-cbba-1f5ce2080000 pid=2274->guuid=807581a0-1a00-0000-cbba-1f5c3b0b0000 pid=2875 clone guuid=57550074-1900-0000-cbba-1f5ce4080000 pid=2276 /tmp/rizzx.x86 guuid=e4f7ed73-1900-0000-cbba-1f5ce3080000 pid=2275->guuid=57550074-1900-0000-cbba-1f5ce4080000 pid=2276 clone guuid=f4280874-1900-0000-cbba-1f5ce5080000 pid=2277 /tmp/rizzx.x86 dns net send-data zombie guuid=e4f7ed73-1900-0000-cbba-1f5ce3080000 pid=2275->guuid=f4280874-1900-0000-cbba-1f5ce5080000 pid=2277 clone guuid=f4280874-1900-0000-cbba-1f5ce5080000 pid=2277->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 35B 5b063f5c-af84-587e-9321-c96a2d578797 pls.ddosme.web.id:69 guuid=f4280874-1900-0000-cbba-1f5ce5080000 pid=2277->5b063f5c-af84-587e-9321-c96a2d578797 send: 19B guuid=807581a0-1a00-0000-cbba-1f5c3b0b0000 pid=2875->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 875B 310a0ed0-c544-54ca-bf3f-fca55e459297 65.222.202.53:80 guuid=807581a0-1a00-0000-cbba-1f5c3b0b0000 pid=2875->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B f63bb08d-417f-5920-b683-9374227cae67 pls.ddosme.web.id:80 guuid=79d34ca1-1a00-0000-cbba-1f5c3e0b0000 pid=2878->f63bb08d-417f-5920-b683-9374227cae67 send: 149B guuid=7ddf45f1-1a00-0000-cbba-1f5ca90b0000 pid=2985->f63bb08d-417f-5920-b683-9374227cae67 send: 98B guuid=23e8b44a-1b00-0000-cbba-1f5c410c0000 pid=3137->f63bb08d-417f-5920-b683-9374227cae67 send: 148B guuid=a13916b1-1b00-0000-cbba-1f5cae0c0000 pid=3246->f63bb08d-417f-5920-b683-9374227cae67 send: 97B guuid=33c3e11c-1c00-0000-cbba-1f5c7d0d0000 pid=3453->f63bb08d-417f-5920-b683-9374227cae67 send: 149B guuid=86a5a547-1c00-0000-cbba-1f5cca0d0000 pid=3530->f63bb08d-417f-5920-b683-9374227cae67 send: 98B guuid=dbc4b674-1c00-0000-cbba-1f5c270e0000 pid=3623->f63bb08d-417f-5920-b683-9374227cae67 send: 149B guuid=c981f7b2-1c00-0000-cbba-1f5cc40e0000 pid=3780->f63bb08d-417f-5920-b683-9374227cae67 send: 98B guuid=48547bf6-1c00-0000-cbba-1f5c810f0000 pid=3969->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=68bcdaf7-1c00-0000-cbba-1f5c860f0000 pid=3974 /tmp/rizzx.i686 guuid=48547bf6-1c00-0000-cbba-1f5c810f0000 pid=3969->guuid=68bcdaf7-1c00-0000-cbba-1f5c860f0000 pid=3974 clone guuid=54bb1b25-1e00-0000-cbba-1f5ca8120000 pid=4776 /tmp/rizzx.i686 guuid=48547bf6-1c00-0000-cbba-1f5c810f0000 pid=3969->guuid=54bb1b25-1e00-0000-cbba-1f5ca8120000 pid=4776 clone guuid=d48c2825-1e00-0000-cbba-1f5ca9120000 pid=4777 /tmp/rizzx.i686 net send-data zombie guuid=48547bf6-1c00-0000-cbba-1f5c810f0000 pid=3969->guuid=d48c2825-1e00-0000-cbba-1f5ca9120000 pid=4777 clone guuid=f63ce4f7-1c00-0000-cbba-1f5c870f0000 pid=3975 /tmp/rizzx.i686 guuid=68bcdaf7-1c00-0000-cbba-1f5c860f0000 pid=3974->guuid=f63ce4f7-1c00-0000-cbba-1f5c870f0000 pid=3975 clone guuid=3cf0e8f7-1c00-0000-cbba-1f5c880f0000 pid=3976 /tmp/rizzx.i686 dns net send-data zombie guuid=68bcdaf7-1c00-0000-cbba-1f5c860f0000 pid=3974->guuid=3cf0e8f7-1c00-0000-cbba-1f5c880f0000 pid=3976 clone guuid=3cf0e8f7-1c00-0000-cbba-1f5c880f0000 pid=3976->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 35B guuid=3cf0e8f7-1c00-0000-cbba-1f5c880f0000 pid=3976->5b063f5c-af84-587e-9321-c96a2d578797 send: 18B guuid=d48c2825-1e00-0000-cbba-1f5ca9120000 pid=4777->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 700B guuid=d48c2825-1e00-0000-cbba-1f5ca9120000 pid=4777->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=5187f725-1e00-0000-cbba-1f5cae120000 pid=4782->f63bb08d-417f-5920-b683-9374227cae67 send: 151B guuid=a5b09c67-1e00-0000-cbba-1f5c67130000 pid=4967->f63bb08d-417f-5920-b683-9374227cae67 send: 100B guuid=db1f1aa8-1e00-0000-cbba-1f5c26140000 pid=5158->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=da6084a8-1e00-0000-cbba-1f5c29140000 pid=5161 /tmp/rizzx.x86_64 guuid=db1f1aa8-1e00-0000-cbba-1f5c26140000 pid=5158->guuid=da6084a8-1e00-0000-cbba-1f5c29140000 pid=5161 clone guuid=e467f8d2-1f00-0000-cbba-1f5c88140000 pid=5256 /tmp/rizzx.x86_64 guuid=db1f1aa8-1e00-0000-cbba-1f5c26140000 pid=5158->guuid=e467f8d2-1f00-0000-cbba-1f5c88140000 pid=5256 clone guuid=2024fed2-1f00-0000-cbba-1f5c89140000 pid=5257 /tmp/rizzx.x86_64 net send-data zombie guuid=db1f1aa8-1e00-0000-cbba-1f5c26140000 pid=5158->guuid=2024fed2-1f00-0000-cbba-1f5c89140000 pid=5257 clone guuid=120e8da8-1e00-0000-cbba-1f5c2a140000 pid=5162 /tmp/rizzx.x86_64 guuid=da6084a8-1e00-0000-cbba-1f5c29140000 pid=5161->guuid=120e8da8-1e00-0000-cbba-1f5c2a140000 pid=5162 clone guuid=885d90a8-1e00-0000-cbba-1f5c2b140000 pid=5163 /tmp/rizzx.x86_64 net send-data zombie guuid=da6084a8-1e00-0000-cbba-1f5c29140000 pid=5161->guuid=885d90a8-1e00-0000-cbba-1f5c2b140000 pid=5163 clone guuid=885d90a8-1e00-0000-cbba-1f5c2b140000 pid=5163->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 700B guuid=885d90a8-1e00-0000-cbba-1f5c2b140000 pid=5163->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=2024fed2-1f00-0000-cbba-1f5c89140000 pid=5257->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 525B guuid=2024fed2-1f00-0000-cbba-1f5c89140000 pid=5257->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=2f4875d3-1f00-0000-cbba-1f5c8b140000 pid=5259->f63bb08d-417f-5920-b683-9374227cae67 send: 149B guuid=6521b72c-2000-0000-cbba-1f5c93140000 pid=5267->f63bb08d-417f-5920-b683-9374227cae67 send: 98B guuid=8b49e989-2000-0000-cbba-1f5c98140000 pid=5272->f63bb08d-417f-5920-b683-9374227cae67 send: 148B guuid=254463c6-2000-0000-cbba-1f5c99140000 pid=5273->f63bb08d-417f-5920-b683-9374227cae67 send: 97B guuid=6b2c2f0b-2100-0000-cbba-1f5ca7140000 pid=5287->f63bb08d-417f-5920-b683-9374227cae67 send: 149B guuid=5f4ca648-2100-0000-cbba-1f5cae140000 pid=5294->f63bb08d-417f-5920-b683-9374227cae67 send: 98B guuid=98214389-2100-0000-cbba-1f5cc4140000 pid=5316->f63bb08d-417f-5920-b683-9374227cae67 send: 149B guuid=782f03dd-2100-0000-cbba-1f5cc5140000 pid=5317->f63bb08d-417f-5920-b683-9374227cae67 send: 98B guuid=66cfb12f-2200-0000-cbba-1f5cca140000 pid=5322->f63bb08d-417f-5920-b683-9374227cae67 send: 149B guuid=5094d780-2200-0000-cbba-1f5ccb140000 pid=5323->f63bb08d-417f-5920-b683-9374227cae67 send: 98B guuid=5e0689d8-2200-0000-cbba-1f5cd0140000 pid=5328->f63bb08d-417f-5920-b683-9374227cae67 send: 148B guuid=b766e517-2300-0000-cbba-1f5cd1140000 pid=5329->f63bb08d-417f-5920-b683-9374227cae67 send: 97B guuid=848c025b-2300-0000-cbba-1f5cd6140000 pid=5334->f63bb08d-417f-5920-b683-9374227cae67 send: 148B guuid=45c63fab-2300-0000-cbba-1f5cd7140000 pid=5335->f63bb08d-417f-5920-b683-9374227cae67 send: 97B guuid=2c209a00-2400-0000-cbba-1f5cdc140000 pid=5340->f63bb08d-417f-5920-b683-9374227cae67 send: 149B guuid=612dbc54-2400-0000-cbba-1f5cdd140000 pid=5341->f63bb08d-417f-5920-b683-9374227cae67 send: 98B guuid=8250b0ad-2400-0000-cbba-1f5ce2140000 pid=5346->f63bb08d-417f-5920-b683-9374227cae67 send: 148B guuid=57a0af02-2500-0000-cbba-1f5ce3140000 pid=5347->f63bb08d-417f-5920-b683-9374227cae67 send: 97B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-02-18 19:14:37 UTC
AV detection:
22 of 38 (57.89%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 33446f98e49714ac509ef7a5f542c9bb557968f2a640f104ce27fca80d576580

(this sample)

  
Delivery method
Distributed via web download

Comments